Commit 5ba92c

2025-06-20 06:52:55 David Sommerseth: Added CVE-2025-3908 and CVE-2025-50054
Security Announcements.md ..
@@ 3,6 3,8 @@
This page lists all security announcements made by the OpenVPN project.
# Announcements
+ * [CVE-2025-50054 - Buffer overflow in OpenVPN ovpn-dco-win version 1.3.0 and earlier and version 2.5.8 and earlier](./CVE-2025-50054) (June 2025)
+ * [CVE-2025-3908 - OpenVPN 3 Linux, openvpn3-admin init-config follows symlink](./CVE-2025-3908) (June 2025)
* [CVE-2024-28882: OpenVPN in a server role accepts multiple exit notifications from authenticated clients which will extend the validity of a closing session](./CVE-2024-28882) (June 2024)
* [CVE-2024-5594: control channel: refuse control channel messages with non-printable characters in them](./CVE-2024-5594) (June 2024)
* [CVE-2024-4877: Windows: A malicious process may spoof the interactive service and potentially impersonate a local user](./CVE-2024-4877) (June 2024)
0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9